What Is Identity Theft? Definition, Common Types, and How Records Are Affected
Identity theft is the misuse of someone else's personal information, such as a Social Security number, bank account details, or date of birth, to commit fraud or obtain money, credit, or services. The victim's own records, credit reports, and accounts can be affected even though the victim did nothing wrong.
This guide is general educational information for U.S. readers. It is not financial advice and does not describe your individual credit file. Figures such as score ranges and timeline estimates are typical examples, not promises.
Key takeaways
- Identity theft is the use of another person's identifying information to commit fraud or obtain money, credit, or services.
- The main types of identity theft include new account fraud, account takeover, tax identity theft, medical identity theft, child identity theft, synthetic identity theft, and criminal identity theft.
- A credit report is a record held by Equifax, Experian, and TransUnion, and fraudulent accounts and inquiries can appear in it alongside legitimate ones.
- The FCRA gives consumers the right to a free credit report from each nationwide agency every 12 months, and the three agencies currently provide free reports weekly through AnnualCreditReport.com.
- An initial fraud alert lasts 1 year, an extended fraud alert lasts 7 years, and a security freeze is free to place, temporarily lift, or remove under federal law.
- Identity theft can be reported at IdentityTheft.gov, and tax-related cases can also be reported to the IRS using Form 14039.
Identity theft is the use of another person's personal information — a Social Security number, bank account number, date of birth, or similar identifier — to commit fraud or to obtain money, credit, or services. The person whose information was used is the victim even when the resulting accounts are later removed from a credit report. The identity theft meaning covers a wide range of situations, from a single stolen card number to a tax return filed in someone else's name.
Identity theft definition and meaning
In plain terms, identity theft is a mismatch between who a person is and who a record says they are. Someone obtains personal data belonging to another person and uses it to pass as that person, or to create a record in that person's name. The Federal Trade Commission publishes consumer education on the subject and collects reports from the public.
The term is often confused with two related ideas. A data breach is an event in which a company's records are exposed, and a breach may or may not lead to identity theft. Fraud is the broader category of deception, and identity theft is one form of it. A stolen card number used for a single purchase is fraud against an account; a Social Security number used to open a new account is identity theft against a person.
How personal information is obtained
Identity thieves rarely rely on one method. Commonly described routes include:
- Data breaches at businesses, medical providers, schools, or government agencies.
- Phishing messages, calls, or copycat websites that request account credentials or personal identifiers.
- Lost or stolen wallets, mail, tax documents, or devices.
- Change-of-address or mail-forwarding requests filed in another person's name.
- Records exposed inside a household, including by relatives or acquaintances.
- Information published or overshared online, such as a full date of birth or a pet's name used as a security answer.
Because the underlying identifiers — a name, a birth date, a Social Security number — do not change, information taken in one incident can be reused years later.
The main types of identity theft
Consumer protection agencies and credit reporting agencies group these crimes by what the thief is trying to obtain. The categories below are the ones most often described in public education material.
| Type | What is used | What is affected |
|---|---|---|
| New account identity theft | Name, Social Security number, birth date | Credit files held by the three nationwide agencies |
| Account takeover | Existing account numbers and login credentials | Individual bank, card, or utility accounts |
| Tax identity theft | Social Security number | Tax filings and refunds at the IRS |
| Medical identity theft | Name and health insurance information | Medical records and insurance benefits |
| Child identity theft | A minor's Social Security number | A credit file that may be reviewed years later |
| Synthetic identity theft | A real identifier combined with invented details | Files that blend a real person's data with a fictional identity |
| Criminal identity theft | Another person's identifying details | Criminal and court records |
More than one type can occur at the same time. A stolen number used to open a phone account may also appear as an unpaid collection account on a credit report.
How identity theft shows up on a credit report
A credit report is a record of accounts and inquiries tied to a consumer's file at Equifax, Experian, and TransUnion. When a fraudulent application is approved, the resulting account can appear in that file, along with the hard inquiry created by the application. Hard inquiries typically remain on a credit report for 2 years, while most negative information, including late payments, stays for 7 years. A Chapter 7 bankruptcy remains for 10 years and a Chapter 13 bankruptcy for 7 years.
Federal law governs how those records are handled. The Fair Credit Reporting Act, enacted in 1970 and amended by the Fair and Accurate Credit Transactions Act in 2003, gives consumers the right to a free credit report from each nationwide agency every 12 months; the three agencies currently provide free reports weekly through AnnualCreditReport.com. Under the FCRA, a credit reporting agency generally must investigate a dispute within 30 days, a period that can extend to 45 days when the consumer provides additional information during the initial 30-day window.
The FCRA addresses identity theft directly as well. Section 605A, at 15 U.S.C. section 1681c-1, covers fraud alerts. An initial fraud alert lasts 1 year, and an extended fraud alert lasts 7 years. Section 605B, at 15 U.S.C. section 1681c-2, covers blocking information that resulted from identity theft when a consumer submits an identity theft report. Under federal law, a security freeze is free to place, temporarily lift, or remove. Our credit freeze page explains how a freeze differs from a lock.
Why fraud alerts, freezes, and reports exist
Each tool addresses a different part of the problem. A fraud alert asks businesses to take extra steps before extending credit in a consumer's name. A security freeze restricts access to a credit file so that new creditors generally cannot view it. A dispute requires a credit reporting agency to investigate a specific item. The Consumer Financial Protection Bureau publishes consumer tools on fraud and scams; the CFPB was created by the Dodd-Frank Act in 2010 and began operating in 2011.
Reporting identity theft
Reports matter because many legal remedies are triggered by documentation. The federal government maintains a single reporting site at IdentityTheft.gov, which produces a personal recovery plan and an official report that can be used with credit reporting agencies, creditors, and law enforcement. Tax-related cases can also be reported to the IRS using Form 14039. Filing the same facts in more than one place is normal, because the credit reporting agencies, the IRS, and law enforcement each keep separate records.
Where credit scores fit in
Credit scores are separate from credit reports. Most credit scores, including FICO and VantageScore, use a range of 300 to 850, and they are calculated from the information in a credit report rather than from reports of fraud itself. FICO's published factor weights are approximately: payment history 35%, amounts owed 30%, length of credit history 15%, new credit 10%, and credit mix 10%. VantageScore uses its own factor weighting and does not publish fixed percentages. Fraudulent accounts recorded in a file can therefore be reflected in the factors those models consider, which is why a credit profile is reviewed after a confirmed incident. Our guides on how credit scores are calculated and FICO compared with VantageScore describe the underlying mechanics.
Detection and monitoring as a records process
Identity theft is often discovered by accident — through a denied application, a collection notice, or a tax filing rejected as a duplicate. Because the crime depends on records rather than on the victim's behavior, detection depends on reviewing those records. The credit check page explains what a credit report review covers, and the credit monitoring page describes services that watch files and accounts for changes. The Federal Reserve also publishes broad consumer credit statistics in its G.19 release, which reports total outstanding consumer credit; that data is aggregate and does not identify individual incidents.
Two framing points matter for this topic. First, a fraudulent account is a records problem, not a personal failure. Second, the remedies that exist — fraud alerts, freezes, dispute investigations, and identity theft report blocking — are defined by statute, with time limits and documentation requirements that apply the same way to every consumer.
The broader identity theft hub collects the related pages on this site, and the credit score hub covers how scoring models treat the account information a report contains.
This page is published for education only and is not financial advice.
Compare three-bureau credit scores and reports from a single place. Educational links, disclosed below.
Three Bureau Credit Scores and ReportsCreditMonitored.com may earn a commission from partner links at no additional cost to you.
Frequently asked questions
What is the simplest identity theft definition?
Identity theft is the use of another person's personal information — such as a name, Social Security number, or account number — to commit fraud or to obtain money, credit, or services in that person's name. The person whose information was used is the victim whether or not they lost money directly.
What are the main types of identity theft?
Public education material typically groups the crime into new account identity theft, account takeover, tax identity theft, medical identity theft, child identity theft, synthetic identity theft, and criminal identity theft. Each type affects a different set of records, such as credit files, tax filings, medical records, or court records.
Does identity theft always appear on a credit report?
No. New account fraud and account takeover usually leave traces in credit files, but tax identity theft, medical identity theft, and criminal identity theft generally show up in other records, such as IRS filings, insurance records, or court documents.
How long does a fraud alert last?
Under the Fair Credit Reporting Act, an initial fraud alert lasts 1 year and an extended fraud alert lasts 7 years. Fraud alerts are covered by FCRA section 605A at 15 U.S.C. section 1681c-1.
Is a security freeze free?
Yes. Under federal law, a security freeze is free to place, temporarily lift, or remove. A freeze restricts access to a credit file so that new creditors generally cannot view it.
Where is identity theft reported?
Reports can be filed at IdentityTheft.gov, which produces an official report and a recovery plan. Tax-related cases can also be reported to the IRS using Form 14039. Credit reporting agencies, the IRS, and law enforcement each keep separate records, so the same facts are often filed in more than one place.
Related guides
- How Credit Scores Are Calculated
- Fico Vs Vantagescore
- Credit Score Ranges Explained
- Payment History And Credit Scores